Bio
I find the threads connecting problems to their solutions. For nine years I have made a living breaking into systems: Active Directory forests, Linux-only and macOS-only networks, control-network and OT environments, web applications, cloud tenants, enterprise and experimental LLMs, and even the physical doors.
As a Red Team Principal Consultant I have operated inside some of the most heavily defended network environments in the world. Before that, at a national bank, I helped build a Red Team from the ground up and came up through three roles in under three years.
I hold OSCE3 (OSEP, OSED, OSWE) and OSCP, and my vulnerability research includes CVE-2021-40124, a local privilege escalation to SYSTEM in Cisco AnyConnect.
I build as well as break. I've automated and administered a company's vulnerability management fleet. Designed, built, and implemented command and control services and the implants under their control. Recent work is local AI, with an emphasis on tooling that augments operations, such as retrieval-augmented generation that puts key details at an operator's fingertips in seconds.
Services Offered
| Red Team / Adversary Emulation Objectives are yours, written for whatever you need proven. Common ones are reaching the internal network from your external footprint, proving that PII or PHI can be reached, accessing key code repositories, emulating a supply chain compromise, and reaching an isolated OT network through the networks in front of it. I work with no prior knowledge unless you decide otherwise, and the report covers how your detection and response changed what I was able to do. Four to six weeks of operations, two weeks of reporting. |
| Internal Penetration Testing Announced, internal network only, no social engineering. The Blue Team is aware of the testing and records detections without obstructing it. What the test is after is the paths of least resistance through your network, and if you want detection data supplied afterwards I will work it into the report. Two weeks of testing, two weeks of reporting. |
| External Penetration Testing Reconnaissance and exploitation of everything reachable from the internet, done the way it is done before an adversary gets inside rather than the way a vulnerability scan does it. Social engineering can be added upon request. One to two weeks of testing, two weeks of reporting. |
| Web Application Testing Authentication, authorization, business logic, and the OWASP Top Ten attack paths. One to three weeks depending on how many applications, two weeks of reporting. |
| AI and LLM Security Testing Your models and the systems wrapped around them. Tested for jailbreak and code execution, for data and model poisoning, for improper output handling, for vector and embedding weaknesses, and more. The wiring gets the same attention as the model, the tools it is allowed to call and what those tools can reach. Findings show what is exploitable and what it hands an attacker. Two weeks of testing, two weeks of reporting. |
| Lateral Research Advisory HIRE A HACKER You bring the problem you are stuck on and it does not have to be a security problem. I approach it the way a hacker approaches a target. You get a debrief and a report of what was discovered, including any code or materials created during the process, worked examples, and test results. Length is set by the problem and agreed before it starts. |
| Local AI and Agent Setups Local AI that your business can run without needing a subscription. Most of this work begins with working out what you actually need, which may be a cluster, a single workstation running a local model tuned to your use case, or both. Then it gets built, with a way to start, stop and manage the whole thing. Two weeks, scoped to what you need running, built and worked through with your team. |
| Education and Tabletop Exercises Virtual or in person, on cyber security or on AI, pitched at the depth your audience actually has, with tabletop exercises worked against your own environment instead of a stock scenario. |
Contact
To start, email the address below and say which of the listed services you are interested in. I reply within one calendar day.
PGP public key (ed25519, expires 2028-09-10)
8C1B 1C7D F5D1 587B 0C8A 555A 6C09 C1B2 A598 97F5
signed statement tying that key to this address, 2026-09-11